SecAlerts
tj-actions logo

tj-actions

Security Risk Profile

66
/100
high

Security Risk Score

Comprehensive risk assessment based on 12 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from December 4, 2023 to present

12
Total CVEs
5
Critical+High
3
Exploited
0
Unpatched

Threat Assessment

Avg CVSS
9.2
Base severity
Avg EPSS
67%
Exploit probability
Unpatched
0
Critical/High
Risk Level
66/100
high
⚠️ 3 Active Exploits 1 Zero-Days

Severity Distribution

Critical
3
High
2
Medium
0
Low
0

Exploit Likelihood

>50% chance
1
20-50%
0
5-20%
0
<5%
0

Age Distribution

Common Weaknesses (CWE)

1
Command Injection
3
2
Input Validation
2

Most Affected Products

1. tj-actions changed-files11
2. tj-actions branch-names3
3. SpotBugs SpotBugs3
4. reviewdog Reviewdog3
5. tj-actions eslint-changed-files3

Recent Vulnerabilities

See more →
CVE-2025-54416
CVSS 9.1critical

tj-actions/branch-names Contains Command Injection Vulnerability

7/25/2025
https://www.theregister.com/2025/04/07/github_supply_chain_attack/
unknown

That massive GitHub supply chain attack? It all started with a stolen SpotBugs token

4/7/2025🔧 No Patch
https://www.bleepingcomputer.com/news/security/recent-github-supply-chain-attack-traced-to-leaked-spotbugs-token/
unknown

Recent GitHub supply chain attack traced to leaked SpotBugs token

4/3/2025⚠ Exploited🔧 No Patch
https://www.bleepingcomputer.com/news/security/coinbase-was-primary-target-of-recent-github-actions-breaches/
unknown

Coinbase was primary target of recent GitHub Actions breaches

3/21/2025🔧 No Patch
https://seclists.org/oss-sec/2025/q1/226
unknown

tj-action/changed-files GitHub action was compromised

3/19/2025🔧 No Patch
https://www.bleepingcomputer.com/news/security/github-action-hack-likely-led-to-another-in-cascading-supply-chain-attack/
unknown

GitHub Action hack likely led to another in cascading supply chain attack

3/18/2025⚠ Exploited🔧 No Patch
https://www.theregister.com/2025/03/18/wiz_github_supply_chain/
unknown

Separate supply chain attack tied to 23K pwned GitHub repos

3/18/2025🔧 No Patch
https://www.theregister.com/2025/03/17/supply_chain_attack_github/
unknown

GitHub supply chain attack spills secrets from 23K projects

3/17/2025🔧 No Patch
CVE-2025-30066
CVSS 8.6EPSS 67%high

tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability

3/15/2025⚠ Exploited⚡ Zero-Day
CVE-2023-52137
CVSS 8.8high

GitHub Action tj-actions/verify-changed-files is vulnerable to command injection in output filenames

12/29/2023

Monitor tj-actions in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.